Rechtliches
Auftragsverarbeitungsvertrag (AVV)
Zuletzt aktualisiert: 2026-09-06
Dieser Vertrag wird bei der Registrierung akzeptiert und gilt für jeden Tarif. Enterprise-Kunden können eine gegengezeichnete Fassung anfordern.
Data processing agreement under Art. 28 GDPR between the customer ("controller") and Teleroids.io ("processor") for the Caicle service.
1. Gegenstand und Dauer
The processor processes personal data on behalf of the controller to provide the Caicle service as described in the terms and the documentation. The agreement runs for the term of the service contract and ends with the deletion or return of the data under section 8.
2. Art und Zweck
Storage and processing of account and workspace data; collection, storage and analysis of company research data from public registers and the company's own filings; generation of scores, summaries and plans with machine-learning models; hosting, backup and support. Person research is limited by system rule to professional roles.
3. Datenarten und betroffene Personen
- Data subjects: the controller's users; contact persons and executives of researched companies in their professional role; the controller's clients where the controller resells the service.
- Types of data: name, business email, role and organisation of users; names, roles and professional contact details of executives and contact persons as published in registers, legal notices and company websites; usage and log data.
- Special categories: none. Private-life data is out of scope by system rule.
4. Pflichten von Verantwortlichem und Auftragsverarbeiter
The processor processes personal data only on the controller's documented instructions, including the settings the controller chooses in the service, unless required to do so by law. The processor ensures that persons authorised to process the data are bound to confidentiality, implements the measures in section 6, supports the controller under sections 7 and 9, and informs the controller without undue delay if an instruction in its opinion infringes data-protection law. The controller is responsible for the lawfulness of the processing, including a legal basis for outreach and the information duties under Art. 13 and 14 GDPR, for which the service generates a notice on every dossier.
5. Unterauftragsverarbeiter
The controller gives general authorisation for the subprocessors listed below and in the trust centre. The processor informs workspace owners by email at least 30 days before adding or replacing a subprocessor; the controller may object on reasonable data-protection grounds, in which case either party may terminate the affected service. The processor imposes equivalent data-protection obligations on each subprocessor by contract.
| Zweck | Anbieter | Standort | Garantie | Seit |
|---|---|---|---|---|
| Hosting, database and agent sandbox | EU hosting provider | EU | DPA, ISO 27001 | 2026 |
| Email delivery | Transactional email provider | EU | DPA | 2026 |
| Payments | Stripe | EU/US | DPA, SCCs | 2026 |
| Model inference | Model provider (per configured key) | EU or US depending on provider | DPA, SCCs where applicable; bring-your-own key available | 2026 |
| Web search | Search providers (per configured key) | Varies | DPA where available; query text only | 2026 |
| Analytics | Self-hosted, cookieless | EU | No third party | 2026 |
6. Technische und organisatorische Maßnahmen
- Encryption in transit (TLS) and at rest, including provider keys and MCP credentials
- Tenant isolation through row-level security in the database
- Agents and tools run in a sandbox with no route to the database and no shell
- Outbound network access from the sandbox only through an egress allowlist
- Role-based access control, least privilege for staff, and multi-factor authentication for administrative access
- Logging of administrative actions, approvals and security events
- Encrypted backups in the EU with regular restore tests
- Secure development practice, dependency monitoring and a vulnerability disclosure contact
7. Unterstützung bei Betroffenenrechten
The processor supports the controller with appropriate technical and organisational measures in fulfilling requests from data subjects under Art. 15 to 22 GDPR, in particular through export and deletion functions in the service. Requests received directly by the processor are forwarded to the controller without undue delay.
8. Löschung und Rückgabe
At the end of the service the controller may export its data for 30 days. After that the processor deletes all personal data, including backups within the backup rotation period, unless the law requires longer storage. Deletion is confirmed on request.
9. Prüfung
The processor makes available the information necessary to demonstrate compliance with Art. 28 GDPR, including this agreement, the trust centre and available certifications of its hosting provider, and allows for and contributes to audits by the controller or an auditor mandated by the controller, with reasonable notice, during business hours and no more than once a year unless a supervisory authority requires otherwise.
10. Haftung
Liability follows Art. 82 GDPR and the liability provisions of the terms of service. Each party is responsible for the fines and damages attributable to its own breach of this agreement.